Status: Findings and recommendations only. Nothing in this file changes the plan of
record, approves a decision, or authorizes code. Gate A (Ivan’s approval of CD-1…CD-10 +
LB1/LB2 in TODO.md) is still unsigned as of this writing.
Audience: a future agent session — any model, including Opus-class — picking up this project with zero conversational context. Everything needed to understand and act on the findings is spelled out here. Read §0 first; it defines every term and rule you need.
Produced by: the 2026-07-06 analysis session (Claude Fable 5). Method in §3.
Read this before acting on §0 (amendment, 2026-08-15). This audit was written for a context-free session and its §0 doubles as an operating brief, so two of its rules have to be corrected here rather than left to be discovered. The code exists. Implementation began on 2026-07-11 under an explicit owner override of CD-8, so §0.1’s “only documentation — zero application code” and §0.3’s rule 4 (“no production code, no scaffolding until Gate A is signed and WP-S7 reads GO”) describe a gate that has been opened. Gate A itself is partially signed as of 2026-07-10 — the three decision boxes are signed, the two physical acts are not — so the front-matter’s “still unsigned” is half stale and half still true. A session reading rule 4 today should not refuse to work; it should know that the override covered dispatching only and relaxed nothing else — not a security invariant, not the
LABEL-MEratification (all Phase-0 numbers remain PROVISIONAL), and not the commit rule.Rule 2’s parenthetical is also stale:
docs/is no longer untracked. The rule it decorates — never commit or push without an explicit ask — is unchanged and still binding, as are all of §0.3’s security invariants in rule 5, which the built system implements rather than merely promises.Everything else in §0 remains the correct orientation, and the finding registers below are preserved as written. Where a specific finding has since been overtaken, it is noted in place; where it has not, silence means it is still open. The current-truth snapshot for a fresh session lives in the project-state record, not here.
agenthropic is a planned self-hosted, local-first dashboard for observing Claude Code agent/subagent activity on Ivan’s Mac Mini M4 — persisted subagent DAG, dollar-accurate cost, Telegram alerts. It is a greenfield build (decided over forking any of six audited rival dashboards). As of 2026-07-06 the repository contains only documentation — zero application code — by design: canonical decision CD-8 forbids production code until the Phase-0 feasibility spike returns GO.
| Term | Meaning |
|---|---|
| CD-1…CD-10 | The ten canonical decisions, resolved in docs/analysis/concept-analysis-v2.md §3. |
| LB1 / LB2 | The two load-bearing decisions: LB1 = ingest primacy (JSONL-primary, contingent on Phase 0); LB2 = personal-first / commercial-clean identity. |
| WP-xx | Work package in docs/analysis/development-plan.md (75 WPs, 8 tracks: S spike · F foundation · D data · IN ingest · C cost · U realtime/UI · A alerts · X delivery). |
| DOC-xx | Documentation work package in docs/DOCS-PLAN.md (33 WPs, 6 tracks P/O/A/S/C/U). |
| Gate A | Ivan’s formal sign-off on CD-1…CD-10 + LB1/LB2. Unsigned. Until signed, the entire plan is recommendation-only. |
| WP-S7 / GO | The Phase-0 spike’s final GO / CONDITIONAL-GO / NO-GO verdict. Gates WP-F1 (the first scaffold WP) — i.e. gates all production code. |
| The probe | docs/analysis/phase0-probe.md — a 2026-07-04 read-only empirical probe of the real ~/.claude/projects corpus that pre-answered CD-1 with CONDITIONAL-GO → build, confidence 85. It de-risks but does not replace the formal spike. |
| Best-path memo | docs/analysis/best-path-decision.md — the strategic memo that sits above the development plan. Its §6 lists plan amendments that were never applied (finding AMEND-1…6). |
| The moat | Per the best-path memo: persistent cross-session DAG + dollar-cost attribution — only these two. (Older docs and the public site say four or five features; see finding LEDGER-23.) |
| P0 tests | Three merge-blocking release tests: (1) Σ tokens == JSONL exact; (2) double replay produces a byte-identical DB; (3) DAG rebuilt from JSONL alone. (As built, 2026-08-25: main is branch-protected on the ci check, so “merge-blocking” here means merge-blocking for anyone who is not the repository owner — enforce_admins is deliberately off for this single-maintainer repository; see the standing correction.) |
| events_raw | The immutable append-only ingest substrate (CD-2). Everything else (sessions, agents, edges, token_usage) is a deterministic, replayable projection. |
| OPCⁿ | An undefined token inherited from the vendor documents. Nobody has ever defined it. Flagged “define-or-drop” since v2 §7; still open (OPEN-9). |
| The five daily questions | The MVP requirement set (CD-10): what is running now · where did tokens/money go · what did session X spawn and why · what failed/stuck · what changed across sessions. Target: answerable in <30 s. |
These come from CLAUDE.md (root + project) and are not optional:
docs/ is currently untracked.CLAUDE.md, WORKLOG.md, .claude/, docs/ai/, *.docx) are
git-excluded via .git/info/exclude and never enter commits or PRs.package.json, src/, workspaces) until
Gate A is signed and WP-S7 reads GO. This audit does not change that.claude spawner, mandatory DASHBOARD_TOKEN with
timingSafeEqual (fail startup if unset), same-origin realtime stream (SSE per CD-5),
no SSRF, tunnel-only remote access, SQLite WAL + tested backups, token counts read
from ~/.claude/projects/*.jsonl — never inferred.WORKLOG.md entry (English) per meaningful task.| Layer | Files | Git status | Role |
|---|---|---|---|
| Sources | 4 .docx under due-diligence/ (vendor due-diligence v1 + v2; ideen-doklad base + EXPANDED) |
excluded | Externally produced inputs. The two families sit on opposite sides of the digests: the vendor docx are upstream of DESIGN.md; the ideen-doklad docx are downstream (they cite DESIGN.md as input). |
| Digests | docs/ai/DESIGN.md · docs/independent-due-diligence.md |
excluded / tracked-eligible | Design basis + the audit that overturned the vendor recommendation. |
| Dossier | docs/due-diligence/ — 6 modules + 6 per-project deep dives |
tracked-eligible | file:line evidence for every rival grade (simple10 A−, hoangsonww B−, nirdiamant C+, cast C, disler C−, claude-code-templates C). |
| Analysis chain | docs/analysis/: concept-analysis (v1) → external-docs-review → concept-analysis-v2 → development-plan → best-path-decision → phase0-probe (+ animated-room-analysis, README) |
tracked-eligible | The decision spine. |
| Trackers | TODO.md · DONE.md · WORKLOG.md (excluded) |
mixed | Live state. Gate A lives at the top of TODO.md. |
| Public site | docs/site/ — 44 pages, 13 ADRs, 603 internal links, 0 broken |
tracked-eligible | The only public surface (app itself is loopback-only). |
| Docs plan | docs/DOCS-PLAN.md |
tracked-eligible | 33-WP decomposition of the site. |
When two documents disagree, resolve in this order (newest evidence wins):
1. docs/analysis/phase0-probe.md (empirical measurements, 2026-07-04)
2. docs/analysis/best-path-decision.md §6 (strategy memo — "sits above the plan")
3. docs/analysis/concept-analysis-v2.md (CD-1…CD-10, LB1/LB2)
4. docs/analysis/development-plan.md (75-WP decomposition)
5. TODO.md (live tracker)
docs/ai/DESIGN.md is the design basis. The probe-§8 amendment order against it was
executed on 2026-07-06 by a 50-agent propagation workflow (see the DONE.md entry
“Propagated the four empirical CD-1 corrections”) — spawn-tool keying, layout mechanism,
outbox demotion and the CD-1 verdict are now consistent corpus-wide (spot-verified by
this audit: the only remaining Task mentions in DESIGN.md, WP-IN8 and docs/site/ are
correction statements). The best-path §6 amendments (AMEND-1…6) were NOT part of that
propagation and remain unapplied.
Why this matters: layers 4 and 5 are approximately six amendments behind layer 2
(see AMEND-1…6). A reader who takes development-plan.md or TODO.md literally will
build the wrong v1.0 (alerts on the critical path, vector-DB stub included, dual SQLite
driver, unslimmed spike).
.docx extracted via textutil and diffed
against the digests (Appendix A).Each finding: statement · evidence · impact · fix. IDs are stable — cite them in future WORKLOG entries when resolving.
The best-path memo states “the plan is being amended to match (see §6)”. That amendment never happened. These six findings are the single largest consistency debt in the repo.
development-plan.md’s critical path still terminates in
A5→A8→A9→A10 (alerts), and TODO.md Phases 5–6 still stage the full alerting stack as
v1.0 work. Fix: re-annotate the critical path; mark Phases 5–6 as post-1.0.docs/DOCS-PLAN.md §5 — written after the memo — explicitly says
“WP-X11 stays”, directly contradicting it. Fix: delete from both, plus the DOCS-PLAN
reconciliation note.packages/core (server/web-import-free) to the scaffold. best-path
§6.7. No scaffold WP mentions it; WP-F1’s layout predates the memo. Cheap now,
expensive after scaffold.Agent/Workflow, never Task (0 Task blocks — a
Task-keyed parser builds an empty DAG); layout is spawn-mechanism-driven (flat
agent-*.jsonl for Agent, nested workflows/wf_*/ for Workflow — 85.2% of agent
files nested), not CC-version-driven. A 50-agent propagation workflow applied this
(plus the outbox demotion and the CD-1 verdict) across DESIGN.md, WP-IN8 and all of
docs/site/ on 2026-07-06 (DONE.md entry), with an adversarial residual sweep
reporting zero misses — independently spot-verified by this audit (every remaining
Task hit is a correction statement). Kept in the register as the one worked example
of precedence being materialized correctly; AMEND-1…6 still await the same treatment.events_raw immutability. ADR-0004/0006/0009 enforce
no-UPDATE/no-DELETE on events_raw by trigger + test; ADR-0012/WP-D10 mandate a
retention TTL sweeper. Flagged open in architecture/data-model.md and
operations/backup-restore.md §4; resolved nowhere. This is a genuine design collision
that will surface as a red build in Track D. Recommended resolution (architect lens,
§9.2): retention deletes projections only; events_raw ages out by segment archival
(file-level detach), never row DML — preserving the triggers and the replay P0 test.'unknown' missing from agents.status CHECK. The reference DDL
(data-model.md, glossary.md, ADR-0006) allows ('working','waiting','completed','error'),
but WP-IN12’s missing-Stop watchdog assigns 'unknown'. Self-flagged in three pages,
fixed in none. Also an unanswered follow-up: the unknown→revert rule (v2 §7 q5).operations/backup-restore.md §5 wires the redactor at WP-IN14 with
a Phase-2 exit criterion. Pick one.security/remote-access.md
defers to security/model.md, which also doesn’t decide it. Security-sensitive,
circular, unowned.architecture/hooks.md prose reads as if already settled.model_pricing is versioned and CI-gated
(no-price-row fails CI) but nobody chose where prices come from or how verified_on
gets refreshed.Status of this register on 2026-08-15. The nine OPEN items were lifted out of this audit into open-decisions.md, which is now where their current state is maintained; read that file rather than this list when you need to act on one. Most of them have since been answered by implementation — the code picked a transport, a port, a hook-auth mechanism, a status vocabulary and a coverage threshold — but answered by implementation is not the same as decided, and none of the sign-off boxes in
open-decisions.mdhas been ticked. Two of the items above are also wrong as stated and are corrected there: OPEN-6 rests on averified_oncolumn that does not exist in the shippedmodel_pricingtable, and OPEN-8’s premise (a boundary between “>90%” and “≥90%”) was overtaken by a 100% threshold — while its “blocks merges” clause turned out to be the unexamined half, and was still false on 2026-08-15, becausemainwas unprotected. (As built, 2026-08-25:mainis branch-protected, the required status check isci— the job id in.github/workflows/ci.yml, not the workflow’sCIdisplay name — and force-pushes and branch deletion are refused. The clause holds for a contributor and, by deliberate choice, not for the repository owner:enforce_adminsis off because agenthropic has one maintainer whose normal working mode is a direct push tomain, and admin enforcement would lock the sole maintainer out of their own repository. See the standing correction.) OPEN-1 (retention) and OPEN-9 (OPCⁿ) remain open in the plain sense: undecided, unowned, and now with more surface area than they had here.
From the source-vs-digest audit (full detail in Appendix A):
query_source = main/subagent/auxiliary — directly
relevant to ingest strategy as a corroborating (or fallback) signal; plus LiteLLM
gateway, claude-token-lens, Anthropic Console/Analytics API.contributing/testing.md
admits its 12-scenario gate does not reproduce them. Recovering them is ~30 minutes.docs/independent-due-diligence.md §0 and DESIGN §0.
Related: DESIGN §0’s claim that greenfield is “reinforced, not weakened, by the
independent audit” overstates — the audit recommended forking simple10, and vendor v1’s
explicit “building from scratch is not justified” argument is never rebutted anywhere.journal.jsonl + promptId is item 11 of the probe’s parser gate but was never
demonstrated. P0 test #3 (“DAG rebuilt from JSONL alone”) depends on it. No WP owns
proving it before Phase 3 relies on it. Fix: add it to the formal spike (WP-S5 scope).claude-code-templates --analytics) is
empty AND the probe is messy. The probe half resolved favorably; the friction log was
never started, scheduled, or closed out. Either run it (passive, near-zero effort) or
record explicitly that the probe’s strength (confidence 85) retires it. The dangling
state is the worst option.README.md is stale on three counts: (a) “ingests Claude Code
lifecycle hooks into SQLite” — CD-1 inverted this to JSONL-primary with hooks as
liveness; (b) “stack and structure are being decided” — the stack is effectively decided
(Fastify + TypeBox, better-sqlite3 single driver, React/Vite/D3, pnpm, Node 22), pending
only Gate-A signature; (c) no mention that a plan of record and a 44-page docs corpus
exist.CLAUDE.md lags the decision chain: still says “stack & repo
structure are an open decision — do not scaffold” (the do-not-scaffold half is still
correct; the open-decision half is not) and “same-origin check on the WebSocket”
(canonical transport is SSE per CD-5/ADR-0007). Every future session reads this
file first — it is actively misleading agents.DONE.md is missing the docs-site milestone (2026-07-04: 22 pages + 13
ADRs authored by a 22-writer/22-reviewer fan-out, 44 pages / 603 links / 0 broken —
recorded only in DOCS-PLAN’s status block and WORKLOG). The stated convention
(“completed milestones move to DONE.md”) is broken for the largest artifact since the
probe.LICENSE file. contributing/licensing.md asserts “the project’s own
MIT posture” and applies Berne-convention logic to rivals (no LICENSE file ⇒
all-rights-reserved ⇒ clean-room only). By its own logic, agenthropic itself is
currently all-rights-reserved. The LB2 commercial-clean hedge is void until a LICENSE
lands.contributing/governance.md but exist nowhere and no WP
owns creating them (“natural fit alongside WP-X6/X9” is a suggestion, not an
assignment).animated-room-analysis.md gates itself on the old numbering — its “not before
Phase 2, ideally after Phase 4” now silently means something different. Any doc that
says “Phase N” without naming the scheme is ambiguous.docs/due-diligence/README.md
and recommendation.md still instruct “fork simple10, graft cast analytics.ts
~50 LOC” — dead advice twice over (greenfield per best-path; cast is clean-room-only
per CD-9). A reader entering the corpus through the dossier gets obsolete instructions
with no pointer forward.Full 33-decision ledger was compiled; below, everything not simply OK. (“OK” = consistent everywhere: security posture — the single most consistent decision in the corpus — SSE transport in the analysis chain, React/Vite/D3, Fastify+TypeBox, scope/five questions, secrets handling, per-artifact licensing rule, pricing structure, gate discipline, token ground truth.)
| Decision | Status | Where it stands |
|---|---|---|
| v1.0 contents / critical path | CONTRADICTED | best-path (no alerts) vs dev-plan/TODO (alerts in). AMEND-1/2. |
| Vector-DB WP-X11 | CONTRADICTED ×3 | best-path deletes; TODO schedules; DOCS-PLAN §5 blesses. AMEND-3. |
| SQLite driver | CONTRADICTED | best-path: single; WP-D2 + CD-9 copy-list: dual. AMEND-4. |
| WP-S1 scope / WP-S4 demotion | CONTRADICTED | best-path §6.6 vs TODO full-scope. AMEND-5. |
Spawn-tool keying (Agent/Workflow) |
RESOLVED 2026-07-06 | Probe proved it; the 50-agent propagation carried it into DESIGN + WP-IN8 + the whole site. AMEND-7. |
| Monorepo layout | SUPERSEDED, unconsolidated | v1 packages/* → v2 apps/* → +packages/core (§6.7). No single doc states the final layout: apps/server, apps/web, packages/shared, packages/core, packages/test-fixtures, hooks/. |
| Durable outbox WP-IN11 | SUPERSEDED cleanly | Probe: YAGNI-leaning, deferrable; TODO annotated correctly; dev-plan body text unamended. |
| Moat definition | CONTRADICTED in framing | Dossier/site: 4–5 features incl. alerting; best-path: 2 (persistent DAG + dollar cost). Public positioning and build strategy tell different stories. LEDGER-23. |
| Fleet status | INCONSISTENT ×3 | roadmap “future decision” vs the-moat “not scheduled” vs faq “is scheduled”. Canonical: deferred until a second host exists (ADR-0002/0012). |
| Docs generator | INTERNALLY INCONSISTENT | DOC-P1 marked deferred, yet adr-docs-site-generator (ADR-0013) exists and content lives at docs/site/ (a path neither DOC-P1 option names). |
| Ingest primacy (LB1/CD-1) | OK in chain; STALE-TEXT in README | Root README still hooks-primary. PROC-1. |
| Transport SSE (CD-5) | OK in chain; residual WS wording | project CLAUDE.md + three site diagrams still say WebSocket/”WS/SSE”. PROC-2, C3. |
All 44 pages respect the seven invariants — zero violations; two pages even strengthen them (auth on all endpoints including reads; restore-drill instance also loopback+token). The 19 real inconsistencies:
| ID | Issue | Pages |
|---|---|---|
| C1 | Fleet status in three versions | roadmap / the-moat / faq (+ “Phase 5+” citations blur deferred→scheduled) |
| C2 | Fastify asserted as fact while stack is formally a leaning — the only style-guide violation in the corpus | architecture/hooks.md, security/model.md (vs overview, what-is, contributing/index) |
| C3 | Residual “WebSocket/SSE” wording vs canonical SSE | what-is (diagram), overview (own diagram), threat-model (diagram+prose) |
| C4 | 12 hooks listed unhedged; everywhere else hedged 12-assumed/9-documented (SubagentStart, PermissionRequest, PostToolUseFailure unconfirmed) | guide/what-is-agenthropic.md |
| C5 | agents.status CHECK lacks 'unknown'; WP-IN12 assigns it (= OPEN-2) |
data-model, glossary, ADR-0006 vs troubleshooting |
| C6 | TTL sweeper vs no-DELETE triggers (= OPEN-1) | ADR-0004/0006/0009 vs ADR-0012/WP-D10 |
| C7 | Redaction Phase 1 vs Phase 2 (= OPEN-3) | ADR-0012 vs backup-restore §5 |
| C8 | “>90%” vs “≥90%” coverage; ADR-0009 self-contradicts (= OPEN-8) | testing, model.md, ADR-0001/0004/0009 vs contributing/index, governance |
| C9 | Illustrative DDL drifts across three pages (compaction column ×3 names; model vs model_id; PK types) |
data-model vs cost-model vs ADR-0006 |
| C10 | hoangsonww DAG described oppositely | comparison (“persisted parent_agent_id”) vs the-moat (“never persisted”) |
| C11 | Telegram phase: DESIGN §9 says 2, plan says 5 | flagged in overview/data-model, unresolved at source |
| C12 | Delegation-savings: DESIGN §9 Phase 4 vs plan Phase 3 | cost-model, glossary |
| C13 | Hook-POST auth settled-in-prose, open-in-question-list (= OPEN-5) | hooks.md vs its own open questions |
| C14 | “Four non-negotiable constraints” vs nine-rule catalogue, no mapping | threat-model vs model.md |
| C15 | “Four things it lacks” vs “five capabilities absent” in one page | what-is-agenthropic.md |
| C16 | Project license absent while licensing posture asserted (= PROC-4) | licensing.md vs governance.md |
| C17 | Circular deferral on token transport (= OPEN-4) | remote-access ↔ model.md |
| C18 | App port uncommitted; tunnel examples have nothing to bind to (= OPEN-7) | remote-access, comparison |
| C19 | Port name TokenReader vs TokenSource never picked |
ADR-0008 |
Cheapest high-value fixes: C1, C3, C4, C8, C10, C16.
The project is an inverted pyramid: a large, high-quality documentation mass on top of zero code — intentional (CD-8), but producing three systemic effects:
Counterweights, equally real: the security core is remarkably coherent at every layer (zero invariant violations across ~70 files); data-as-truth (JSONL ground truth, persisted edges, tokens × dated price) runs unbroken through all layers; process hygiene (WORKLOG, git-exclusions, no attribution, no unasked commits) has been followed flawlessly; and the corpus is unusually self-aware — most defects found by this audit were already self-flagged in-page, just never resolved.
The pyramid is no longer inverted (note added 2026-08-15). Code exists — a little over 17,000 lines with 106 test files beside it — so the structural diagnosis that opens this section has expired. Two of the three systemic effects it predicted did not survive contact with the build, and one did. Effect 1 is the one that survived, and it survived exactly: the remaining blockers are still human. The spike ran and returned CONDITIONAL GO, Gate A is still only partially signed, and the items nobody but Ivan can perform — hand-labelling the
LABEL-MEcorpus, running the friction log, enabling branch protection — are still the whole of what is outstanding. Effect 2 has reversed direction: the code is now the amending authority, and documentation that disagrees with it is what gets corrected, which is why this note exists. Effect 3, the split between the public story and the strategy, is best judged against the site as it stands today rather than against this paragraph’s 2026-07-06 reading of it.The counterweights held. The security invariants are implemented, not merely written down; ground truth is still read from the JSONL and never inferred; and the corpus’s habit of flagging its own defects in-page is the reason a build could be reconciled against it at all.
host_id in the
first migration, no RBAC) — and literally void until a LICENSE file exists (PROC-4).Two of these four have moved (note added 2026-08-15). The commercial hedge is no longer void: an MIT
LICENSEsits at the repository root, closing PROC-4. The coverage figure in scale vs capacity is now 100% rather than ≥90%, which makes the paragraph’s point about team-grade process serving a solo owner stronger, not weaker. The customer paragraph is untouched by anything that has been built: the friction log was still never run, the dissent is still unanswered, and the “<30 s” figure in the value proposition has never been measured — it is an exit gate that has been neither passed nor failed, because nobody has timed it. The market paragraph’s warning about churning Anthropic internals is the one to keep watching; the parser now defends against layouts it has never seen in the wild, which is preparation, not evidence.
The five daily questions (CD-10) are the real functional requirements and they are good: user-phrased, measurable, with a numeric target (<30 s). The quantified acceptance criteria (hierarchy ≥95%, zero lost raw events, Σ tokens exact) are rare quality for a pre-code project. What’s missing: a formal FR/NFR layer in the plan of record (EXPANDED §3 had FR-01…10 + NFRs incl. PRIV-01/PERF-01; never transplanted — LOST-5), personas/JTBD (same), and upward traceability — no definition of how anyone will know the dashboard actually saves time post-launch. Cheapest fix: add the FR/NFR IDs as a column to the existing CD table, and let the friction log double as the baseline measurement.
The spine is right: events_raw (append-only, idempotency-keyed) + deterministic
projection is event-sourcing-lite at exactly the right weight; persisted
orchestration_edges with derived_from_event_id makes the moat auditable; nine named
ports keep the core testable; SSE is the correct transport for a one-way stream.
Four real concerns, in pain order:
events_raw ages out via segment-level archival
(detach a closed period into an archive file; deletion is a file operation, not row
DML) — the no-UPDATE/DELETE triggers and the replay P0 test survive intact.packages/core has no owner (AMEND-6). Add it to WP-F1 before scaffold; it is
expensive to retrofit.The stack is effectively decided — Fastify + TypeBox, better-sqlite3 (single driver),
React/Vite/D3, pnpm, Node 22 — and CLAUDE.md should stop calling it open (PROC-2),
because every agent session reads that file first. The final monorepo layout has never
been consolidated into one sentence anywhere (see ledger row); writing that paragraph is
high-value.
Practical risks from the implementer’s chair: (1) the hardest module is the JSONL parser,
not the UI — 85% of agent files are nested and the 11-item gate should become literally
the skeleton of the first test suite (WP-S5); (2) one-WP-one-PR across 75 WPs is heavy
for a solo owner — after applying §6, merge mechanical WPs into wave-sized PR series
(e.g. D5–D8); (3) coverage-from-commit-one means WP-F3 (the harness) must genuinely land
first or early PRs lie; pick ≥90% vs >90% once (OPEN-8); (4) two site pages already
promise concrete paths (apps/server/src/security/token-guard.ts) — at scaffold time,
either honor them or fix the pages.
On paper the strategy is above standard: three P0 release blockers, a three-tier golden corpus (raw/redacted/manifested) with four pathologies, QA stop-the-release authority, tested restore per release candidate. The gaps:
Measurably the emptiest zone of the corpus: across ~70 files there are zero wireframes,
zero user flows, zero information architecture, zero visual language. Everything that
exists on the topic: the five questions + <30 s target (CD-10), the usage/dashboard.md
stub, four view names (WP-U6…U9) — and, only in the git-excluded EXPANDED docx, the
7-screen UX model (§15), the honest-uncertainty principle, and PERF-01 (LOST-6). The
project’s best UX thinking is buried in a file agents cannot see.
What is concretely missing, by weight:
layoutTree/physics
is a starting point; nobody recorded which of its interactions survive.Recommendation: one lightweight design WP (WP-UX0), dependency-ordered before WP-U5: IA map, five question-to-screen flows, sketch/ASCII wireframes for the four views, the uncertainty visual language, and transplanting EXPANDED §15 + PERF-01 into the plan of record. Roughly one day of work; without it Phase 4 starts with invisible design debt and a <30 s target no screen was designed to hit.
Items marked (Ivan) require his decision; the rest are executable by an agent session on request. Never commit any of this without an explicit ask.
TODO.md top). Everything else is
recommendation-only until then. Done when: the two Gate-A checkboxes flip or a dated
deferral note is added.development-plan.md + TODO.md — AMEND-1…6 in one
editorial pass. Done when: no alerts on the critical path; A8/A9 cut; X11 deleted
(incl. DOCS-PLAN §5 note); WP-D2 single-driver; S1 slimmed/S4 demoted; packages/core
in WP-F1; each edit cites best-path §6.docs/ai/DESIGN.md per probe §8 (AMEND-7)'unknown' to the status CHECK + define the
revert rule, pick redaction Phase 1 or 2. Done when: one dated decision note lands in
concept-analysis-v2 §7 (or a new ADR) and data-model.md/ADR-0006 are updated.claude-code-templates --analytics baseline logging starts with an end date, or a
dated retirement note is added to best-path §9.LICENSE (MIT) (Ivan approves) + record the docs-site milestone in DONE.md
(PROC-3/4). Done when: LICENSE exists and DONE.md has the 2026-07-04 docs entry.README.md and project CLAUDE.md (PROC-1/2): JSONL-primary framing,
stack-decided-pending-Gate-A, SSE. Done when: no hooks-primary or WebSocket or
stack-open wording remains.contributing/testing.md.Causal position: the vendor due-diligence docx (v1, v2) are upstream of the digests; the ideen-doklad docx (base, EXPANDED) are downstream — they cite DESIGN.md, independent-due-diligence.md and WORKLOG as inputs. So vendor content absent from the digests is “lost in digestion”; ideen-doklad content absent is “never folded back”.
Vendor v1 → v2: same recommendation (adopt hoangsonww), but v2 introduces the 8-criterion weighted scoring model in which simple10 wins 4.1 vs 4.0, then overrides the result on the visualization axis — the exact paragraph the independent audit attacks. Grade change disler B+→B; hoangsonww test files 67→65; adds §12 feature matrix, §13 adjacent tools, §16 risk register, §17 cost model, §18 threat model, §19 integration blueprint, §20 roadmap (~6 developer-days), appendices A–G.
Ideen-doklad base → EXPANDED: 11 → 26 sections. EXPANDED adds FR/NFR catalogue,
personas/JTBD, numeric MVP metrics (≥95% hierarchy, 0 lost events, <30 s), ADR-001…010,
negative-test catalogue, QA gates A–F, UX screen model + honest-uncertainty, risk
register R-01…R-10 (adds R-09 DB growth, R-10 false confidence from inferred data),
23-item backlog, traceability matrix, release checklist. Unresolved schema fork between
the two: base = single events + webhook_targets/webhook_deliveries; EXPANDED =
events_raw+events + alert_deliveries. v2/CD-4 adopted the EXPANDED shape; the
alert-tables divergence resurfaces in WP-A2 and was never explicitly reconciled.
Digest claims not supported by sources: the “no true DAG” verbatim quote (LOST-8); DESIGN §0’s “reinforced, not weakened” framing (both sources recommend fork-not-build; v1 explicitly says building from scratch is not justified — never rebutted); DESIGN’s Phase 1.5 animated-room material comes from a later separate analysis, outside DESIGN’s declared sources. Also noted: the independent audit reports simple10 at 78 test files vs the vendor’s 76 without comment.
Generation-quality note: EXPANDED §§10.1–10.7 repeat an identical four-row table seven times; the base doc contains a stray Hindi-script token. Both docx are partially templated — treat their apparatus (IDs, catalogues) as valuable and their prose volume as inflated.